Comment Re:Can AI (Score 1) 59
uninstall kwalletmanager.
uninstall kwalletmanager.
And the winner is...
Acrtic:
USSR 38011
(NB The first list of mine referred to the Atlantic)
Countries and total activity released:
UK 35087 TBq
Switzerland 4419.3
USA 2942.2
Belgium 2120.3
France 353.4
Netherlands 336
Sweden 3.3
Pacific:
USSR 874
USA 554.4
Japan 15
https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fwww-pub.iaea.org%2FMTCD%2F...
Anyway what do you mean by "our" team? Everyone, every thing and every penny in this study is French.
A code received by SMS counts as 2FA, so that can be your way out of apps for now.
Good catch. Officially, 0-14 are 14.2% of the population https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fec.europa.eu%2Feurostat%2F...
The EU app supports offline options, one of them going to an official service (e.g. Post Office) who have an interface to accept requests based on checking your physical ID.
, everyone is trying to force 100% phone adoption. There must be some vast extra attack surface on phones that desktops don't have
It's the contrary, it's that phones are locked down and therefore "secure" in some sense. The attack surface to tamper with the phone OS (without being detected) is small, making it hard to cheat for identity attestation.
It would make more sense to have a EU made - if you want 100% government controlled - social network for kids.
Just this clearly isn't an approach compatible with European way of doing things. Your proposal of "100% government controlled", which is the very definition of government overreach. Also, the EU isn't allowed to compete with businesses (by making an app that goes onto the market to compete with TikTok etc.). The government sets the rule for businesses to exist. The rule is: you can make a social network, but you are responsible for making sure no kids are there. It's a simple and reasonable approach, similar to how you can open a strip club and you are responsible to make sure no kids are there.
Also, more advanced threat 22: "An adult enrols with their own identity on a minor's phone or passes the enrolment credentials to it, so that the minor holds a batch of valid "over 18" proofs and can pass age checks independently, without the adult being involved in each check."
Comment: "This is the provisioning form of the collusion risk accepted in T-08: a willing adult can always give a minor access, whether per check, per batch, or by lending credentials. Closing it would require binding each presentation to the enrolled person's biometrics, which was rejected as a disproportionate invasion of privacy for a yes/no age check. The design instead limits the duration (3-month validity, mandatory re-identification) and the scale (single-use batches, per-device issuance, velocity limits) of the abuse — individual family-level collusion remains possible but does not scale into a service. The remaining risk is addressed by parental controls, education and national enforcement."
https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fageverification.dev%2Fav...
The risk was identified in the threat model as "Cheating during enrolment: A minor obtains a genuine "over 18" proof by cheating at the start: using a borrowed, forged or stolen identity document, or defeating the face check with a photo, mask or deepfake." The risk was accepted with the following comment: "Accepted given the bounded consequence (an "over 18" boolean, not an identity), the 3-month re-check, and continuing improvement of detection technology. Deployments should track the presentation-attack-detection certification level of their chosen biometric vendor." https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fageverification.dev%2Fav...
The possible collusion between the issuer and a website was identified in the threat model: "A deliberately non-compliant issuer that secretly retains fingerprints could link presentations reported to it. This requires active wrongdoing by a regulated, audited entity (a Trusted-List-registered provider subject to GDPR and national supervision) plus verifier cooperation". https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fageverification.dev%2Fav...
Why would a large, government-designated entity like a bank with or the national Post Office service, use such illegal metods, just to de-anonymize your visits? Can you propose a practical scenario where this would make sense?
Does it? I regularly access my accounts on five different UK banks from my Raspberry Pi and I don't use an App to verify on any of them.
You need 2FA since EU directive "PSD2" from 2015 (since then, the EU has updated to PSD3). It was implemented in the UK and requires "Strong customer identification" https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fsprintlaw.co.uk%2Farticl... However, it is possible that the UK legal implementation imposed 2FA only for payment (money getting out of your account) and maybe not for consulting your balance.
And yet you still have to trust that this system doesn't get back-doored by three-letter agencies.
The "three-letter agencies" discover no new information here. They ALREADY know your name, date of birth, browsing history, online purchase history.
This gives the "yes/no" entity the power to completely shut down any person's ability to do anything meaningful online
Nothing new. The entity is under the same regulatory framework as your bank or your ISP, which already can shutdown your abilities of doing things. It's just another, very limited channel where a bug or intentional action can restrict your abilities to buy liquor and dildos.
And it gives this cabal the ability to shut all sites/services out of the market they don't "like." Requiring they all use this yes/no entity and then refusing participation. (Granted, they kinda already have the option of mucking with DNS and ISP's).
Besides your acknowledgement that they already had the DNS option, the whole "can shot down" doe snot make much sense to me. We are talking about age-restricted businesses doing business in the EU, which are already subject to many rules. If you run a casino or sex shop business in Europe, you already decided to abide by those rules. Those who don't want to obey rules are already subject to whatever systems to block them. The new system does not add anything new. Who would be stupid enough to run a successful online casino, obey by all EU rules until now, then suddenly decide "I don't want to do the age verification thing [because I'm suddenly more libertarian than yesterday]?"
Why not stop this madness and focus on PARENTS?
The European approach has always been, in any problem, to make the burden lie on the business side. In this instance, don't let corporates exploit young people. If some people (children) find workarounds, that's fine, and something we have to live with. But businesses are required to make their best effort to limit the possibility of workarounds.
You visit an online liquor store. The store asks your mobile phone whether you are of sufficient age. Your mobile phone asks the issuer, gets a yes/no token, forwards it to the liquor store. No data was leaked.
In countries where the issuer is "the bank", then in any case both the liquor and the bank already knew everything (the online liquor store already knew your payment details, and your bank already knew you make purchases at the online liquor store).
I'm not supporting Flock (at all), I just that accusing the technician is the wrong approach. If Flock corporate is training technicians top make police reports whenever pictured, and suggesting wording like "harassment" that will trigger police dispatch, then maybe there is an angle of attack against Flock corporate, for wasting time of police officers.
We're here to give you a computer, not a religion. - attributed to Bob Pariseau, at the introduction of the Amiga